By 

A security researcher uncovered a zero-day in Apple software by tweaking a few lines of code. Speaking at Defcon in Las Vegas last week, Patrick Wardle, Chief Research Officer of Digita Security, described his research into “synthetic” interactions with a user interface (UI) that can lead to severe macOS system security issues.

Synthetic events are when attackers can virtually “click” objects in order to load code without user consent. If a threat actor is able to “click” a security prompt and load a kernel extension, this could lead to the full compromise of an operating system.

“Via a single click, countless security mechanisms may be completely bypassed,” the researcher says. “Run untrusted app? click …allowed. Authorize keychain access? click …allowed. Load 3rd-party kernel extension? click …allowed. Authorize outgoing network connection? click …allowed.”

While some users may stop these kinds of attacks when warning dialogue appears, Wardle says that it is possible to synthetically generate clicks silently and in an invisible way — a concept which the researcher says results in “everything pretty much go[ing] to hell.”

Read more at ZDNet.com

Leave a Reply

Discover more from

Subscribe now to keep reading and get access to the full archive.

Continue reading